Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
captn3m0
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
captn3m0
5mo ago
You're right. Found the relevant docs+API calls: https://docs.github.com/en/rest/actions/workflow-runs?apiVer... Also for a Pending Deployment: https://docs.github.com/en/rest/a
62.
▲
by
captn3m0
5mo ago
1. _Multiple third-party companies_ can detect these obviously malicious packages in almost-real-time 2. NPM still not only publishes them, but also keeps distributing them for anything beyond 5 minutes. Microsoft/GitHub/NPM can o
63.
▲
by
captn3m0
5mo ago
https://docs.github.com/en/actions/how-tos/deploy/configure-... is the feature they use. > We impose tag protection rules that prevent release tags from being created until a release deployment succee
64.
▲
by
captn3m0
5mo ago
I've been collecting things you can't pin: - Python inline dependencies in PEP-0723, which you can pin with a==1.0, but can't be hash-pinned afaik. - The bin package manager lets you pin binaries, but they aren't hash-pi
65.
▲
by
captn3m0
5mo ago
The astral blog recently pointed out how they do release gates (manual approvals on release workflows) even with trusted publishing. And sadly, all of the documentation for trusted publishing (NPM/PyPi/Rubygems) doesn't even
66.
▲
by
captn3m0
5mo ago
History explains why HTML is now a living standard: https://whatwg.org/faq (Ctrl+F Living and keep reading). > A published version of the standard NEVER, EVER, EVER, EVER changes. WhatWG does have per-commit snapshots o
67.
▲
by
captn3m0
5mo ago
The k8s exploit requires stars to be aligned for an external attacker: the pod you exploit (via an RCE?) must share some layers with a privileged pod running in the same node. Or alternatively, you should have the ability to run an arbitary
68.
▲
by
captn3m0
5mo ago
IANAL, but as an analogy perhaps: Some of the investments made from FTX stolen assets got amazing gains (Anthropic being a notable investment). But it doesn’t undo the crime.
69.
▲
by
captn3m0
5mo ago
Zend used to maintain a PHP port of Lucene 15 years ago that I used, but not sure what happened to it.
70.
▲
by
captn3m0
5mo ago
Is there a reliable way to trigger percussion?
71.
▲
by
captn3m0
5mo ago
> By agreeing to these Terms, you represent and warrant to us: (i) that you have not previously been suspended or removed from the Websites and Online Services CloudFlare ToS has you covered. A human must accept it, even with the new age
72.
▲
by
captn3m0
5mo ago
One of the sources of that problem is that GitHub is pushing all new products on top of Actions, making it load-bearing. A few examples are Dependabot, Pages, and Copilot Reviews. These aren't products that need to run on a CI system.
73.
▲
A Namecheap bug got my domain suspended
(captnemo.in)
3 points
by
captn3m0
5mo ago
|
0 comments
74.
▲
by
captn3m0
5mo ago
Read a little and turns out Monero requires a chain of programs, each with a Blake hash construction to generate the next one. That makes it very hard to optimise since it adds a layer of “hard to avoid” branching. And this also makes it ha
75.
▲
by
captn3m0
5mo ago
The program is randomly generated and I am guessing that the seed for this is deterministically determined from the current block head (or something similar) making it hard to attack. It might lead to scenarios where a miner may optimise bl
76.
▲
by
captn3m0
5mo ago
If you (like me) are hearing about this for the first time, Bret Taylor is the co-founder. > Bret is Co-Founder of Sierra. Most recently, he served as Co-CEO of Salesforce. Prior to Salesforce, Bret founded Quip and was CTO of Facebook.
77.
▲
by
captn3m0
5mo ago
I've been working on this over the years. WIP is here: https://github.com/captn3m0/electron-survey , and it doesn't look good. I keep getting distracted by side-quests. The last one was building an Electron Zo
78.
▲
by
captn3m0
5mo ago
Seeing as how Canonical launched several Kubernetes products, this strategy didn’t survive for long.
79.
▲
by
captn3m0
5mo ago
Worse than that, these are all vibe coded changes. If you look at any public Anthropocene codebase, they are all vibe coded messes with no coherent vision. I was looking at the Claude Code GitHub Action and it is a mess of options that don’
80.
▲
by
captn3m0
5mo ago
What’s the usecase where you are okay cordoning a node but not okay with just terminating it and starting a new one? Physical nodes where you have to reclaim them and don’t run any virtualisation ?
81.
▲
by
captn3m0
5mo ago
It is more than just a tree of actions, since actions bring in shell scripts and they can download and execute arbitrary code that isn’t pinned.
82.
▲
by
captn3m0
5mo ago
A new problem is that even pinned actions themselves download unpinned transitive dependencies, such as the case with trivy action. Zizmor recently shipped a rule to warn of such actions, but it only does it for two known actions so far.
83.
▲
by
captn3m0
6mo ago
What I want at this point is a classic.github.com which uses the old UI from 2013. That was perfect and fast.
84.
▲
by
captn3m0
6mo ago
1. Code that manages the Kubernetes manifests. This doesn’t need to live alongside your actual app. 2. Code that does injection in eBPF and needs to live along your app. From my understanding from the README and helm chart, these are both i
85.
▲
by
captn3m0
6mo ago
You should split your controller - it is running in both the control and data planes. Idea is good though, wish you luck.
86.
▲
by
captn3m0
6mo ago
Does anyone know what is the "iCloud security code" mentioned? Is it just the 6 digit code that Apple sends to verify iCloud access?
87.
▲
by
captn3m0
6mo ago
Took me 5 minutes to find more: https://github.com/tanaylab/Mendelson_et_al_2023/blob/9c5a65... (Uses Date of Birth column). And some information on how they were distributing it to researchers: https:/
88.
▲
by
captn3m0
6mo ago
These are all made up and likely hallucinated.
89.
▲
by
captn3m0
6mo ago
Link to the API Client is incorrect at the bottom: https://github.com/nhl-stats-api-client instead of https://github.com/liahimratman/nhl-api-client
90.
▲
by
captn3m0
6mo ago
https://platform.claude.com/docs/en/about-claude/model-depre... Retirement date for Opus 4.6 is marked as "Not sooner than February 5, 2027"
More ›